🤖 AI Summary
In fully homomorphic encryption (FHE), noise accumulation and modular wraparound errors severely compromise computational correctness, yet existing compilers lack static noise and overflow analysis capabilities, hindering formal program verification. Method: This paper introduces ILA, a correctness-oriented intermediate language for FHE, which—uniquely—incorporates a type system into FHE compilation. Grounded in an extensible, general-purpose type theory, ILA statically characterizes ciphertext noise bounds and modular arithmetic safety margins across multiple schemes (BGV, BFV, TFHE). Crucially, ILA enables formal modeling and automated verification of noise growth and overflow behavior without requiring secret keys. Contribution/Results: ILA significantly enhances functional correctness assurance for FHE circuits. Experimental evaluation demonstrates efficient verification of representative homomorphic programs, establishing a reliable, formally provable security foundation for FHE application development.
📝 Abstract
RLWE-based Fully Homomorphic Encryption (FHE) schemes add some small emph{noise} to the message during encryption. The noise accumulates with each homomorphic operation. When the noise exceeds a critical value, the FHE circuit produces an incorrect output. This makes developing FHE applications quite subtle, as one must closely track the noise to ensure correctness. However, existing libraries and compilers offer limited support to statically track the noise. Additionally, FHE circuits are also plagued by wraparound errors that are common in finite modulus arithmetic. These two limitations of existing compilers and libraries make FHE applications too difficult to develop with confidence.
In this work, we present a emph{correctness-oriented} IR, Intermediate Language for Arithmetic circuits, for type-checking circuits intended for homomorphic evaluation. Our IR is backed by a type system that tracks low-level quantitative bounds (e.g., ciphertext noise) without using the secret key. Using our type system, we identify and prove a strong emph{functional correctness} criterion for ila circuits. Additionally, we have designed ila to be maximally general: our core type system does not directly assume a particular FHE scheme, but instead axiomatizes a emph{model} of FHE. We instantiate this model with the exact FHE schemes (BGV, BFV and TFHE), and obtain functional correctness for free.